Errors / HTTP errors
403 Forbidden
The server understood the request and refuses to let you see this.
The page, or the file, is unavailable to whoever is blocked; sometimes only some visitors.
Seeing it on someone else’s site?
- The site is deliberately blocking this address or this visitor: not a login problem (that would be 401).
- A VPN, a shared network or an unusual browser can trip a site's firewall; try without the VPN or from another network.
- If it names Cloudflare or says
Error 1020, the site's security rules blocked you; only the site can change that.
Why it happens, if it is your site
- A firewall or bot protection (Cloudflare, a WAF, a security plugin) blocking the request by country, IP, user agent or pattern.
- File permissions on the server: the web server's user cannot read the file or folder.
- A folder with no index file where directory listing is off.
- An
.htaccessor server rule denying access, often left by a security plugin or a migration. - An API key restricted to other domains, or a signed URL that expired.
How to fix it
- Read the 403 page itself: a firewall's page names the firewall and often the rule or a ray ID.
- Check the file's permissions and owner (644 for files and 755 for folders is the usual start) and that the folder has an
indexfile. - Look for
denyrules in.htaccessor the server config, and in a security plugin's settings. - For an API, check the key's allowed referrers include this site.
Whose problem it is
Either the site's own code or a third party's, depending on where it comes from.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- 403 Forbidden on CloudflareCloudflare, in front of the site, decided this request should not reach it.
- 403 Forbidden (nginx)nginx found the path but is not allowed to serve it.
- 403 Forbidden (openresty)The site's server (OpenResty, a build of nginx) refused the request, often through a hosting company's firewall.
- 401 UnauthorizedThe page needs you to be signed in, or a valid key, and the request did not have one.